About WHAWIT

Paging a human is the end
of an investigation, not the start.

WHAWIT is an AI-powered observability, incident management and incident-AI platform with native on-call. It connects read-only to the monitoring tools a team already runs, investigates root cause across logs, metrics and code, and pages the responder with the analysis already attached.

Why we built it

Monitoring has become very good at two things: noticing that something is wrong, and telling somebody about it. Then it stops. The alert lands, and whoever is on call starts from a blank page — opening dashboards, scrolling logs, checking what shipped, correlating one tool against another — before they can even form a first hypothesis. The hardest, slowest part of an incident is the part the tooling hands back to a person, usually the least convenient person at the least convenient hour.

An incident should arrive at a responder with the investigation already done.

That single sentence is the product. Everything below follows from it, and anything that does not serve it does not get built.

Investigation before notification

The Radar agent works the incident across logs, metrics and code — forming a root-cause hypothesis, collecting the evidence behind it, and continuing in cycles whether or not a human is watching.

On-call is not a separate product

Schedules, timezone-aware rotating layers, overrides and escalation policies are native. Paging goes out over WhatsApp, SMS, voice call, Slack, Microsoft Teams, Discord and email.

Read-only ingestion, no rip-and-replace

WHAWIT reads from the monitoring tools already in place — GCP Cloud Logging, CloudWatch, Datadog, New Relic, Sentry, BetterStack — and the investigation writes nothing back to them. What does write is separate and connected on purpose: a ticket in your tracker, incident status mirrored into an on-call tool, or a proposed fix pushed as a branch and opened as a pull request. Letting that pull request merge on its own is an opt-in policy setting, off by default, and you choose the gate it has to pass.

It meets people where the work happens

Response is coordinated in Slack and Microsoft Teams. Tickets are created and kept in sync with Jira, GitHub, Azure DevOps and Linear; incident status syncs separately with Jira, Linear and OpsGenie. A VS Code extension and MCP server bring the investigation into the editor.

Who builds it

Jose Escrich, founder of WHAWIT

Jose Escrich

Founder

Jose Escrich has spent more than 25 years building and operating enterprise systems where downtime, noise and slow incident response carry real cost. WHAWIT is the tool that job kept asking for.

He runs every pilot personally: onboarding, architecture and security review, and evaluation against your real incidents before any broader rollout.

Trusted by enterprise teams

FirstClose logoNexa logoOlivia Education logoSimbuy logo

The company

WHAWIT is built and operated by US3 GROUP LLC. The details a vendor-onboarding form asks for, in one place.

Legal entity
US3 GROUP LLC
Registered address
255 Giralda Ave, Floor 5, Coral Gables, FL 33134, United States

On compliance, so it is not inferred from anything above: a SOC 2 Type I audit is targeted for Q4 2026 / Q1 2027, and WHAWIT is currently in readiness preparation. Security review materials and an architecture walkthrough are part of every pilot. Questions that belong in writing go to [email protected], and anything commercial to [email protected].

See it on your own incidents

A pilot connects read-only to the providers you already run and is evaluated against incidents that actually happened to you. Nothing is ripped out to find out whether it works.

Book a Pilot